6 min read

Why a UPS in Switzerland still matters

The Swiss grid loses 21 minutes a year. On 28 August a storm put the rack on battery for 39 seconds without ever interrupting the power.
Why a UPS in Switzerland still matters
The UniFi 2U UPS, bottom of the rack.

The Swiss grid barely goes down. ElCom’s 2024 figures: the average end consumer saw 0.34 interruptions and 21 minutes of outage, of which only 10 were unplanned. Over ten years the number has sat between 16 and 23 minutes and is trending down.

So a UPS here buys you ten minutes a year of something that was going to be over before you noticed. On those numbers it is hard to justify the rack units.

Then on 28 August 2026 a supercell crossed the plateau, dropped 6 cm hail on Winterthur, sent over seventy people to the Winterthur cantonal hospital and cost insurers just under a billion francs — and the rack recorded 39 seconds on battery.

The power never went out.

The event that does not appear in SAIDI

There was no interruption. The mains was continuous through the whole window. What arrived was a fast, deep voltage sag followed by an overvoltage on recovery.

The grid meter is a Shelly Pro 3EM. It sits on the IoT network and deliberately not on the battery — a meter outside the protected zone, watching the raw house supply. It reported straight through with no gap:

08:05:25Z   362.1 W
08:05:29Z   379.6 W      <- UPS transferred to battery here
08:05:39Z   385.9 W
08:06:03Z   427.1 W

Two instruments in the same building disagreed about whether anything had happened, and both were right. The dip was too fast for that meter’s averaging window, and long enough for the UPS to reject the supply and for the solar inverter to disconnect.

The UPS did not record it either. Its own voltage telemetry never goes down — it steps 225.7 → 228.2 → 232.2 → 227.7 and that is all. The only evidence the sag happened is that the UPS decided to transfer, and that the inverter dropped off seven seconds earlier. The event is visible solely in what the equipment did, never in what it measured.

Down hard, then up and over

                    before    during    peak      settled
UPS output          225.7 V   228.2 V   232.2 V   227.7 V
inverter measured   230.3 V   231.0 V   232.1 V   —

The line came back 6.5 V above where it started and peaked at 10:06:40 — 33 seconds after the mains was already declared restored — then dropped back to about 2 V high.

It was not done. At 10:13:50, eight minutes later, the line dipped to 225.7 V again for thirty seconds. That one the UPS rode through without transferring.

Deep sag, overvoltage on recovery, slow settle: the signature of a fault clearing nearby on the distribution network. Something shorted, voltage collapsed across the local supply, protection opened, and with the load gone the line bounced high until regulation caught up.

UPS output voltage across the event. The sag never appears — the UPS only logged the overshoot that followed, and a second dip eight minutes later.
UPS output voltage across the event. The sag never appears — the UPS only logged the overshoot that followed, and a second dip eight minutes later.

Minute by minute

10:04:20   solar inverter at 4850 W
10:05:21   inverter down to 1726 W, then disconnects — no further samples
10:05:28   UPS: battery power in use              <- 7 s AFTER the inverter tripped
10:05:34   orchestrator poll: on_battery=True, 100%, 1176 s remaining, 320 W
10:06:07   UPS: AC power restored                 <- 39 s on battery, total
10:06:12   AV receiver drops off the network
10:06:40   UPS output voltage peaks at 232.2 V
10:07:40   voltage drops back to 227.7 V
10:13:50   second dip to 225.7 V for 30 s — ridden through, no transfer
10:11:36   solar inverter back on the network, 0 W
10:12:41   inverter running again, 2002 W

The inverter tripped seven seconds before the UPS transferred. Its grid monitoring is the most sensitive disturbance detector in the building, because anti-islanding protection has to be.

The AV receiver is on a wall socket, so it never lost power at any point — there was nothing to lose. It dropped at 10:06:12, while the line was still climbing toward its 232.2 V peak. It failed on the overvoltage, not on an absence of one.

The accidental control group

Same building, same disturbance, two populations:

On the UPS      8 outlets, all stayed energised, none cycled.
                No reboot on any host, switch or access point.
                Min uptime across 7 network devices: 4 days.
                Min uptime across 6 hosts: 25.5 hours.
On wall power   AV receiver power-cycled.
                Solar inverter disconnected 6 minutes, ~0.3 kWh lost.

Nothing on the battery noticed. Two of the things not on it did.

And note what hurt them: a voltage excursion of about 7 V lasting well under a minute. Enough to power-cycle a modern receiver, and enough to make a grid-tied inverter take itself off the grid for six minutes.

It is also the class of event that quietly kills storage. A sag below a PSU’s holdup, a surge on recovery, a disk mid-write — that is how a filesystem gets corrupted without an outage ever appearing in any log.

So: why a UPS here

The advertised case is the blackout. Battery, runway, graceful shutdown. That case is real and the rack is built for it, but on Swiss numbers it fires roughly once every three years and lasts ten minutes.

The case that actually fires is the supply being present but out of spec for a few seconds. A UPS with a proper transfer handles that by disconnecting the load from the mains entirely and running it from the inverter until the line is acceptable again.

The battery is the product, and the runway is what you size it on. But the transfer that gives you the runway also isolates the load from a supply that is present and wrong, and that is the case which fired here.

Which is why “good power supplies” is not a substitute. The receiver has a perfectly good power supply and still went down, and the inverter is equipment engineered specifically around grid conditions — it disconnected on purpose, because the grid was genuinely out of spec.

Across a full week of telemetry, 10’064 samples, there was exactly one on-battery transition pair. It was not a blackout. Full power log for those seven days:

08-22 18:06:20   Device Power Cycled     (an access point, unrelated)
08-28 10:05:28   UPS Battery Power In Use
08-28 10:06:07   UPS AC Power Restored

What it would have done in a real outage

The UPS is a Ubiquiti 2U: 250 W drawn of a 1000 W budget, estimated runtime 1408 s. That is 23 minutes, down to about 15 once the Pi, the 10G switch and the gateway moved onto it.

Fifteen minutes rides out a flicker, not an outage. So the goal was never to stay up — ride out the short ones, and for the long ones shut down cleanly with margin, then come back unattended.

A Raspberry Pi polls the UPS every 10 seconds and arms a shutdown when any of these is true:

Wall clock:   600 s on battery       — first poll that crosses it
Battery:      level < 35%            — 2 consecutive polls
Runtime:      remaining < 360 s      — 2 consecutive polls

On 28 August: 39 seconds, never left 100%, ~1176 s remaining throughout. Not within an order of magnitude of any of them.

The two-consecutive-poll rule is a scar. timeToRemain comes from the UPS’s own estimator and emits garbage in the first seconds after a transition; one bad sample used to be enough to start halting the rack. The wall clock is the unconditional path, because it is the one number that cannot be wrong about how long the mains has been gone.

Coming back is two paths, and the second is the one that gets forgotten:

Cold:  battery drained, hosts genuinely lost power.
       They boot themselves when mains returns.
Warm:  mains returned while hosts sat halted but still fed.
       No AC edge for anything to react to, so the orchestrator
       wakes them: Wake-on-LAN, or IPMI power on.

Warm is the likely case, because a shutdown that beat the battery by six minutes leaves every machine off but powered.

The two layers, and the two ways back.
The two layers, and the two ways back.
The solar inverter's six-minute hole. It tripped seven seconds before the UPS transferred, and recovered without intervention.
The solar inverter’s six-minute hole. It tripped seven seconds before the UPS transferred, and recovered without intervention.

Sources